Identity Lifecycle Management Wasn’t Built for AI Agents

Cybersecurity teams are scrambling to address a critical vulnerability exposed by artificial intelligence (AI) models, highlighting a glaring oversight in identity lifecycle management systems. These systems, designed to grant and revoke access to sensitive resources based on user identities, were not built with AI agents in mind. As a result, organizations worldwide are at risk … Read more

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

A New Wave of Malware Exploits OAuth Vulnerability to Infiltrate Gmail Accounts via Google API A sophisticated malware campaign linked to the ToddyCat threat group has been uncovered, leveraging a previously unknown vulnerability in Google’s OAuth authentication system to gain unauthorized access to Gmail accounts. This alarming development highlights the ongoing cat-and-mouse game between cybercriminals … Read more

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Microsoft 365 Accounts Hijacked in 3 Seconds: The Stealthy Threat of ConsentFix and ClickFix Attacks In a chilling example of modern cybercrime, threat actors are exploiting everyday online habits to hijack Microsoft 365 accounts in just three seconds. This brazen tactic involves manipulating users into surrendering OAuth tokens, granting attackers session access to email and … Read more

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

Cybersecurity experts have recently sounded the alarm about a new and insidious threat, one that could potentially compromise even the most secure systems. It starts with artificial intelligence (AI) models being used to detect software vulnerabilities, but with a twist: these AI models are also being exploited by malicious actors to hijack compute resources. The … Read more

Google loses final appeal to overturn €4.1 billion EU fine

The European Union has reaffirmed its stance on Google’s business practices, dismissing the company’s final appeal against a €4.1 billion antitrust fine. This decision is a significant blow to Google, as it confirms that the tech giant abused its dominant market position by promoting its Chrome browser and search service through Android agreements. At the … Read more

Identity Lifecycle Management Wasn’t Built for AI Agents

Cybersecurity Teams Scramble to Contain Breaches as AI-Powered Attackers Exploit Identity Management Weaknesses A growing threat is emerging in the world of cybercrime, where sophisticated attackers are using artificial intelligence (AI) agents to exploit vulnerabilities in identity lifecycle management systems. These attacks have left many organizations scrambling to contain breaches and wondering how such a … Read more

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

A sophisticated malware campaign linked to the ToddyCat threat actor has been uncovered, exploiting a vulnerability in Google’s OAuth 2.0 authentication system to gain unauthorized access to Gmail accounts via the Google API. The attack leverages the API’s legitimate functionality to quietly collect sensitive user data, raising significant concerns about the security of online services … Read more

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

A Wave of Attacks Exploits AI-Powered Vulnerability Discovery, Leaving Organizations Scrambling for Defense In a disturbing trend that highlights the dark side of artificial intelligence (AI) adoption, attackers are increasingly leveraging AI-powered tools to discover and exploit software vulnerabilities. This development has left many organizations scrambling to bolster their defenses against an evolving threat landscape. … Read more

Opera rolls out Paste Protect feature to fight ClickFix attacks

Opera has taken a significant step in bolstering user protection against sophisticated cyber threats with the introduction of its new Paste Protect feature. This innovative security mechanism is specifically designed to counter ClickFix-style attacks, which have become increasingly popular among threat actors. ClickFix is a cunning technique used by attackers to trick users into executing … Read more

CISA: Microsoft SharePoint RCE flaw now actively exploited

Microsoft SharePoint Servers Under Attack: CISA Warns of Actively Exploited Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to organizations using Microsoft SharePoint servers, indicating that attackers have begun exploiting a high-severity vulnerability in the platform. Tracked as CVE-2026-45659, this remote code execution flaw allows low-privileged attackers to execute … Read more